MCP100 verdict
Useful as a vulnerability-intelligence triage assistant, but every match and remediation decision should be verified against authoritative advisories.
MCP100 Assessment
Editorial verdict
Useful as a vulnerability-intelligence triage assistant, but every match and remediation decision should be verified against authoritative advisories.
Reviewed 2026-08-11 · Next review 2026-09-10
Task Fit
Mapped
Specialized workflows
Trust
Reviewed
A dated editorial review is published on the MCP detail page.
Maintenance
Activity observed
A dated repository or package update is available; editorial maintenance review is still pending.
Popularity
Signals available
Visible usage signals are shown for discovery only, not as proof of safety.
Best for
- Aggregating CVE, exploit, KEV, EPSS, and related security context from the project's supported sources
Not ideal for
- Asset-specific risk acceptance, guaranteed-complete vulnerability scanning, or automated remediation
Avoid if
- A downstream workflow would act on the aggregated result without checking product versions and primary advisory details
Trade-offs
- One interface can speed triage across many APIs, but upstream coverage, rate limits, identifiers, and freshness differ and can produce conflicting evidence.
Evidence scope
Evidence
Popularity
1.1k MCP repository stars
No MCP-specific package metric is stored
Stars observed 2026-08-14T18:46:26.000Z · Downloads observation date unavailable
Exact implementation repository metric.
No exact package is documented.
Maintenance
Publisher activity observed 2026-08-05T08:09:26Z
Current source snapshot
Trust review
Source relationship: Community implementation
Reviewed 2026-08-11 · Next review 2026-09-10